Portfolio-wide COI tracking fails on inconsistency, not volume: the same vendor is compliant in one building and deficient in the next because each building wrote its own requirement. The fix is to standardize the requirement first (one written standard by trade tier), re-baseline every vendor against it, and only then centralize execution in one team, internal or managed.
Picture the same HVAC contractor working in three of your buildings. In the first, the property manager requires a $2 million umbrella and checks the endorsement forms. In the second, the requirement is $1 million and the coordinator accepts whatever the broker sends. In the third, nobody has written a requirement down; the vendor has "always been fine." The contractor carries a $1 million umbrella and no endorsements: deficient in the first building, compliant in the second, unknown in the third, all on the same Tuesday, all under the same ownership.
That is the portfolio problem with vendor certificates of insurance. It is not that there are too many certificates. It is that there are too many versions of the truth. Volume is a tooling question. Inconsistency is a management question, and the answer to it is some combination of two moves: centralize the work, or standardize the rules.
Why is the portfolio problem inconsistency, not volume?
When a portfolio grows from four buildings to forty, three things drift apart.
- Requirements. Each building's vendor requirements were written by whoever was there at the time, often copied from a lease or a prior employer. Limits, endorsements, and additional insured entities vary without anyone deciding they should.
- Rigor. Some coordinators read endorsements; some check dates and file. The same certificate is accepted in one building and rejected in another.
- Records. Compliance lives in five systems and eleven spreadsheets. Nobody can answer "which vendors are compliant portfolio-wide" without a week of work.
The result is a risk profile the asset manager thinks is uniform and is not. A claim in the third building exposes the ownership entity exactly as if the first building's rigor had never existed.
The vendor networks the compliance vendors advertise give a sense of the numbers involved: BCS cites a 78,000-vendor pre-vetted network and Jones 30,000+ vendor profiles. A forty-building portfolio touches hundreds of those vendors, and each building reading them differently is the inconsistency problem in one sentence. Renewal cadences, by contrast, are nearly standard across tools, at 60, 30, and 7 days; the cadence was never the problem.
Option one: centralize the team
Centralizing means one group handles certificate review, chasing, and record-keeping for every building, and property managers at the buildings get a status rather than a task.
What it fixes. Rigor becomes uniform because the same people apply the same reading. Records live in one place. Reporting is one query. The chase becomes a specialty, which makes it faster; a person who calls brokers all day gets better at it than someone who does it once a month.
What it costs. A central team needs a workload model (certificates per analyst per month), a service standard the buildings can rely on (review within one business day, chase started same day), and a way to handle local knowledge: the property manager knows the vendor's principal; the central team does not.
When it is the right first move. When the volume is large enough to justify dedicated people, or when the portfolio is on one property management system and the records can be consolidated easily. Also when the buildings are managed by third parties whose rigor you cannot control; centralizing takes the review away from them without taking away their relationship.
Option two: standardize the requirement
Standardizing means one written vendor insurance standard for the portfolio, by trade tier, with a defined exception process, while execution stays at the buildings.
What it fixes. The drift in requirements ends. A vendor compliant in one building is compliant in all. Brokers learn one requirement and produce cleaner certificates. Exceptions become visible because they are now deviations from something.
What it costs. Someone has to write the standard, and that means decisions: limits by trade, which endorsements are mandatory, how tenant-hired contractors are treated, how legacy vendors are brought up to standard. Lender and insurance requirements at specific assets can force local additions; the standard needs a way to hold "portfolio minimum plus asset-specific" without creating forty variants again.
When it is the right first move. When the buildings run on different systems or different third-party managers and centralizing the work is not practical yet. Standardizing the rule costs nothing in headcount and removes most of the inconsistency on its own.
Should you centralize, standardize, or both?
In practice the durable answer is both, and the order matters.
| Centralize the team | Standardize the requirement | |
|---|---|---|
| What it fixes | Uniform rigor, one record, faster chase | Drift in requirements; brokers learn one standard |
| What it costs | Headcount or a partner; a service standard the buildings rely on | Decisions about limits, endorsements, legacy vendors |
| Right first move when | Volume justifies dedicated people; one PMS across the portfolio | Buildings run on different systems or third-party managers |
| Fails when | Forty standards and no authority to change them | Nobody re-baselines the existing vendors |
- Standardize first. Write the portfolio standard. Three trade tiers, explicit limits and endorsements, exact additional insured entities per ownership structure, and a one-page exception form. Get it signed off by whoever carries the risk.
- Re-baseline every vendor against it. This is the painful step and the honest one. Expect the real compliance rate to drop when the reading gets consistent. That number is the truth; the old one was not.
- Then centralize execution. With one standard, a central team (internal, or a managed operator) can run review, chase, and records for every building the same way, and the buildings keep their vendor relationships.
Doing it in the other order, centralizing first, gives the central team forty standards to enforce and no authority to change them. They become a slow version of the old problem.
Rule of thumb for the standard: if a property manager cannot tell a vendor the insurance requirement in two sentences, it is too complicated to be enforced at the dock.
Reporting that an asset manager will actually read
The reason to do any of this is a report that means something. Portfolio-wide COI tracking produces one page, monthly:
- Vendors in scope, by building and by trade tier.
- Compliant, conditionally approved (with expiry of the exception), deficient, and not yet onboarded, as counts and as a percentage.
- Median days from deficiency to compliant.
- Vendors dispatched while non-compliant in the period, with the exception approver named. This line should be zero, and if it is not, the reasons are the whole conversation.
That last metric is the one we would put on the operations dashboard beside response time and lease-event hit rate; see commercial property management KPIs for the full set.
Whether the central execution is an internal team or a partner is a headcount and capability question. Premise runs COI compliance across portfolios this way, one standard supplied by the client, review and chase run under an SLA, and it cites 7× compliance capacity. One standard is what makes that single review process possible. If you are tooling an internal team instead, how to compare COI tracking software and the vendor onboarding checklist are the two pieces to read next.
Start by asking one question at your next operations meeting: how many written vendor insurance standards does the portfolio have? If nobody knows, the answer is the number of buildings.
Frequently asked questions
Should COI tracking be centralized or handled at each building?
Standardize first, then centralize. A central team enforcing forty different building standards becomes a slow version of the old problem. Write one portfolio standard by trade tier, re-baseline every vendor against it, then move review, chase, and records to one team while buildings keep the vendor relationships.
What should a portfolio vendor insurance standard contain?
Three trade tiers with explicit limits and endorsements, the exact additional insured entities per ownership structure, a rule for asset-specific additions required by lenders or insurers, and a one-page exception form. If a property manager cannot state it in two sentences, it is too complicated to enforce at the dock.
Why does compliance drop after standardizing?
Because the old number was not true. Consistent reading against one requirement exposes certificates that were accepted locally with the wrong entity or missing endorsements. The lower number after re-baselining is the real compliance rate, and it is the one to report.
What should a monthly portfolio COI report show?
Vendors in scope by building and tier; compliant, conditionally approved (with exception expiry), deficient, and not yet onboarded as counts and percentages; median days from deficiency to compliant; and vendors dispatched while non-compliant, with the approver named. That last line should be zero.
Can a managed service run COI compliance across a whole portfolio?
Yes, provided the client supplies one written standard and the partner works in the client's system of record. Premise runs COI compliance this way, and cites 7x compliance capacity; one standard is what makes a single review process possible.